Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Below are some basic guidelines for troubleshooting Check Point Logging issues.
Please note : This guide does not cover issues with any OPSEC LEA based issues.
Please note : The FWD (Firewall Daemon) is responsible for sending and receiving the Check Point Logs on port tcp/257.
Ok, so rst of all are the logs being sent to the Smart Centre Manager or the necessary Log Manager ? We can check this by
con rming whether the gateway is sending the log packets via the FW Log port tcp/257 upon the gateway and the manager. To do
this use either or both of the following commands,
netstat -an | grep 257 - This will show the state of the TCP sockets.
tcpdump -ni [interface name] port 257 - This will show a packet capture of the FW Log packets on the subsequent interface.
If the gateway is not sending the logs then this can be down to one of the following issues,
If the gateway is sending the logs but the SmartCentre / Log Manager is not receiving them then either a device between the 2
nodes is blocking the packets or there is a routing issue.
Why are the logs not being displayed within SmartView tracker ?
Ok so the manager is receiving the logs but you may still not see them within the SmartView tracker this will be down to either the
FWD (Firewall Daemon) or the log les being corrupted.
If the log les are corrupted you should expect to see no logs within the SmartView Tracker. If this is the case you will need to
action the following steps :
Within these steps we rst enable the debug. Then we run a live tail on the log le. And then we run a grep on the live tail for a
speci c error. The live tail allows us to view the end of the log le in real time. We nally turn o the debug.
Below shows an example of an error with the SIC trust between the Gateway and Manager obtained from the $FWDIR/log/fwd.elg,
back to
top
L ATEST ARTICLES
POPUL AR ARTICLES
(http://www.fir3net.com/all-
content-
(http://www.twitter.com/f3lix001)
(https://plus.google.com/b/116663132291058367261/116
rss.html)
About (/Site/about- r3net.html) Sitemap (/sitemap.html) Status (http://monitor. r3net.com) Login (/Log-in.html)